Access Control Vulnerability in FreeScout Help Desk Software
CVE-2025-48473

5.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
29 May 2025

What is CVE-2025-48473?

FreeScout, a self-hosted help desk software, had a significant access control vulnerability prior to version 1.8.179. This flaw allowed users to create conversations from messages in other conversations without appropriate visibility checks. Consequently, unauthorized users could access arbitrary messages from different mailboxes or conversations they were not meant to view. The oversight stemmed from a lack of validation against the 'show_only_assigned_conversations' setting, which is intended to restrict access. This issue was addressed in version 1.8.179 to enhance security measures.

Affected Version(s)

freescout < 1.8.179

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-48473 : Access Control Vulnerability in FreeScout Help Desk Software